Junglewise Threat Intelligence

CVE-2026-61450: Grav Twig sandbox bypass in grav.offsetGet method

CVE-2026-61450 · Severity: medium · CVSS 6.5 · Published 2026-07-10

Technologies: Getgrav Grav, Grav, getgrav/grav (Packagist). Vendors: Getgrav, Grav, Packagist.

Executive brief

Grav, a popular open-source content management system, is affected by a security bypass that allows users with page-editing permissions to steal sensitive system secrets. By using specific commands within a page's content, an attacker can bypass security restrictions to view the site's full configuration, including SMTP email passwords, API keys, and database credentials. This could lead to a broader compromise of the organization's connected services and infrastructure.

Technical details

A Twig sandbox bypass exists in Grav versions prior to 2.0.2 due to an incomplete fix for a previous vulnerability. While the 'config' variable is replaced with a redacted facade, the raw configuration container remains accessible via the allow-listed 'grav.offsetGet('config')' method. Attackers can then use allow-listed object-dumping filters such as 'json_encode', 'print_r', or 'yaml_encode' to serialize the real Config object. Because these filters operate at the PHP level without triggering the sandbox's method gate, they expose the entire configuration tree. This allows any user with 'admin.pages' permissions or filesystem write access to 'user/pages' to exfiltrate sensitive plugin secrets. The issue is addressed in version 2.0.2 by removing 'offsetget' from the allowed methods for the Grav container and hardening object-dumping filters.

Affected products

  • getgrav Grav before 2.0.2

Timeline

  • 2026-06-25: advisory: Original GitHub security advisory published
  • 2026-07-10: disclosed: NVD publication date

References

Related threats